Prompt Injection attack against LLM-integrated Applications
Атаки с внедрением промптов на приложения, интегрированные с большими языковыми моделями
2023-06-08
SCID: 54.1/fbujx5yy
Discuss with AI
HouYiLLM-integrated applicationsapplication prompt theftblack-box attackprompt injection attacks
Figures from the paper
Abstract (AI)
Large Language Models (LLMs), renowned for their superior proficiency in language comprehension and generation, stimulate a vibrant ecosystem of applications around them. However, their extensive assimilation into various services introduces significant security risks. This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications. Initially, we conduct an exploratory analysis on ten commercial applications, highlighting the constraints of current attack strategies in practice. Prompted by these limitations, we subsequently formulate HouYi, a novel black-box prompt injection attack technique, which draws inspiration from traditional web injection attacks. HouYi is compartmentalized into three crucial elements: a seamlessly-incorporated pre-constructed prompt, an injection prompt inducing context partition, and a malicious payload designed to fulfill the attack objectives. Leveraging HouYi, we unveil previously unknown and severe attack outcomes, such as unrestricted arbitrary LLM usage and uncomplicated application prompt theft. We deploy HouYi on 36 actual LLM-integrated applications and discern 31 applications susceptible to prompt injection. 10 vendors have validated our discoveries, including Notion, which has the potential to impact millions of users. Our investigation illuminates both the possible risks of prompt injection attacks and the possible tactics for mitigation.
Key Findings
1
An exploratory analysis of ten commercial LLM-integrated applications exposed practical limitations in existing prompt injection attack strategies.
2
HouYi enables severe attack outcomes, including unrestricted arbitrary LLM usage and straightforward theft of application prompts.
3
HouYi is introduced as a black-box prompt injection technique combining a pre-constructed prompt, context-partitioning injection prompt, and malicious payload.
4
Ten vendors validated the reported vulnerabilities, including Notion, potentially affecting millions of users; the study also discusses mitigation tactics.
5
Testing 36 real-world LLM-integrated applications found 31 susceptible to prompt injection attacks.
Research Object
actual LLM-integrated applications
Research Subject
vulnerability of these applications to prompt injection attacks and the resulting security impacts
Publication Details
Publication Date
2023-06-08
Journal
Publisher
ISSN
Cited by
84
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest